CVE-2026-40966

In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histories, including secrets and credentials, by injecting filter logic through conversationId. Only applications that use VectorStoreChatMemoryAdvisor and pass user-supplied input as a conversationId are affected.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vmware:spring_ai:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_ai:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-28 08:16

Updated : 2026-06-17 10:45


NVD link : CVE-2026-40966

Mitre link : CVE-2026-40966

CVE.ORG link : CVE-2026-40966


JSON object : View

Products Affected

vmware

  • spring_ai
CWE
CWE-284

Improper Access Control